On this page
Ask most vendors if they’re SOC 2 compliant and you’ll get a confident “yes” back within a sentence. Ask a follow-up question — when was the audit, who’s the auditor, is that a Type I snapshot or a Type II window — and the confidence tends to thin out fast. We’d rather just tell you where we actually stand.
Where we actually stand
Beemy is readiness-stage for SOC 2 Type II. Not certified. Not audited. Readiness-stage, and here’s exactly what that means: no auditor is engaged yet, and no observation window has opened. We’re not going to round that up to “compliant” because the controls SOC 2 evidences happen to already be running.
Why the controls being real doesn’t make us certified
Here’s the part that’s easy to blur, so we’ll keep it sharp: SOC 2 Type II isn’t really about building new safeguards from scratch. For us, it’s mostly about naming and evidencing controls the architecture already enforces — the same silo isolation, encryption and deletion guarantees on our Trust page, described in the language an auditor checks against, and proven to hold over a sustained window rather than asserted once.
That’s the distinction that matters: Type II is a window, not a snapshot. An auditor doesn’t take our word for it once — they observe the controls holding over months. We haven’t started that clock. Until we have, “readiness” is the honest word, and “certified” isn’t one we’re going to reach for early just because it reads better on a page.
What’s actually running today
None of this is a promise to build the controls later. The list is concrete, and it’s already live:
- Silo isolation — personal, work and public knowledge in physically separate stores, not a shared database with a flag.
- Envelope encryption + a KMS key hierarchy — per-tenant keys, not one shared secret protecting everyone.
- An immutable, hash-chained audit log — append-only, nothing rewritten after the fact.
- Crypto-shred deletion — deleting an account destroys the keys, not just a row.
- No-train model routing — your content never trains a shared model, enforced at the routing layer.
- TLS 1.3 everywhere data moves.
- An always-on security CI gate — every change ships through automated checks, not a quarterly review.
Every item on that list runs today, in production, regardless of whether an auditor has ever looked at it. That’s the part we’re confident about. What’s left is the audit itself: engaging an auditor and completing the observation window Type II requires.
What we’re not going to say until it’s true
We’re not going to write “SOC 2 Type II certified” on this site before an auditor has actually observed the window close. We’re not going to say “audited” before there’s been an audit. And we’re not going to soften “readiness-stage” into something that reads more finished than it is. When the window closes and the report is in hand, we’ll say exactly that — and not a day before.
If you’re evaluating Beemy for your team and want the specifics — what’s covered, what the timeline looks like, what your compliance team will want to see — that’s exactly what our enterprise conversation is for. Talk to us.